CariDotMy

 Forgot password?
 Register

ADVERTISEMENT

12Next
Return to list New
View: 5101|Reply: 20

Program Autostart.

[Copy link]
Post time 11-6-2007 07:00 PM | Show all posts |Read mode
Problem nye macam ni...  sekarang ni tiap2 kali aku start windows, regedit.exe

akan keluar guna notepad (yg tulis ntah ape2 bahasa) as a startup.

Bile aku run regedit dr 'start menu - run' registry editor tu akan bukak guna notepad gak... sama kes dgn 'MSConfig'.. Tapi lepas aku buat 'exefix' kedua2 program tu dah boleh buka as normal tapi daripada folder EmergencyUtils instead from Windows or Win32 folder.

So far... program yg lain semua running ok. Cuma registry masa startup tu jer yg menyemakkan mata
Ni log daripada  virus remover tu:

============ Remover for Backdoor.Generic3.SVX ===============
Date: 08.02.2007 10:14
C:\WINDOWS\agrsmdel.exe OK
C:\WINDOWS\AGRSMMSG.exe OK
C:\WINDOWS\biwlanappxpver.dll OK
C:\WINDOWS\biwlandrvxpver.dll OK
C:\WINDOWS\ctdrvins.exe OK
C:\WINDOWS\CTRegRun.exe OK
C:\WINDOWS\cttib1.dll OK
C:\WINDOWS\devenum.exe OK
C:\WINDOWS\dla.exe OK
C:\WINDOWS\explorer.exe OK
C:\WINDOWS\hh.exe OK
C:\WINDOWS\icccodes.dll OK
C:\WINDOWS\IsUninst.exe OK
C:\WINDOWS\iun6002.exe OK
C:\WINDOWS\kpcp32.dll OK
C:\WINDOWS\kpsys32.dll OK
C:\WINDOWS\mruninst.exe OK
C:\WINDOWS\NOTEPAD.EXE OK
C:\WINDOWS\pfpick.dll OK
C:\WINDOWS\regedit.exe OK
C:\WINDOWS\RSetupCE.exe OK
C:\WINDOWS\sprof32.dll OK
C:\WINDOWS\TASKMAN.EXE OK
C:\WINDOWS\twain_32.dll OK
C:\WINDOWS\twunk_32.exe OK
C:\WINDOWS\unzip.exe OK
C:\WINDOWS\vmmreg32.dll OK
C:\WINDOWS\Webdelc.exe OK
C:\WINDOWS\winhlp32.exe OK
C:\WINDOWS\wutil.dll OK
Work complete


Aku dah try guna EmergencyUtils tapi still kat startup tu keluar registry pakai notepad.

Sekarang ni aku kena run Registry Editor and MSConfig tu daripada folder EmergyUtils ni...

AntiVirus : AVG
Virus Remover : AVG
Windows : XP Pro SP2ROGRAM

[ Last edited by  trunks at 14-7-2007 08:40 PM ]
Reply

Use magic Report


ADVERTISEMENT


Post time 12-6-2007 10:24 AM | Show all posts
Yuppp.... boleh run HijakThis pastu paste HJT log kat cni?
Reply

Use magic Report

 Author| Post time 12-6-2007 03:37 PM | Show all posts

Reply #8 neotoxin's post

Ni dr log HijackThis. Aku buat 2 bhgn:

1 of 2

Logfile of HijackThis v1.99.1
Scan saved at 10:33:28 AM, on 12-Jun-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\ositp4\ositp4.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Athan\Athan.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\VisualTooltip\VisualToolTip.exe
C:\Program Files\Styler\Styler.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\HPQ\Shared\hpqwmi.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\mspaint.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www-proxy.ericsson.se:3132/accelerated_pac_base.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = isat;proxy:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=explorer.exe, "C:\Documents and Settings\MOHD EZUAN'IZAM\Templates\18281\13418281.exe"
O1 - Hosts: 192.1.1.53 DXXDBM
O1 - Hosts: 192.1.1.54 DXXSRV1
O1 - Hosts: 192.1.1.55 DXXCOMMSRV1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {F1FABE79-25FC-46de-8C5A-2C6DB9D64333} - (no file)
O3 - Toolbar: Alexa - {3CEFF6CD-6F08-4e4d-BCCD-FF7415288C3B} - C:\WINDOWS\system32\SHDOCVW.DLL
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
Reply

Use magic Report

 Author| Post time 12-6-2007 04:40 PM | Show all posts

Reply #8 neotoxin's post

log HijackThis 2/2:

O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [VisualTooltip] C:\Program Files\VisualTooltip\VisualToolTip.exe
O4 - HKLM\..\Run: [Styler] C:\Program Files\Styler\Styler.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O8 - Extra context menu item: Alexa Web Search - http://client.alexa.com/holiday/script/actions/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Get Alexa Data - http://client.alexa.com/holiday/script/actions/sitedata.htm
O8 - Extra context menu item: Mail to a Friend... - http://client.alexa.com/holiday/script/actions/mailto.htm
O8 - Extra context menu item: See Related Links - http://client.alexa.com/holiday/script/actions/related.htm
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Write a Review... - http://client.alexa.com/holiday/script/actions/review.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/wind ... e.cab?1143453769171
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/micr ... e.cab?1143455563343
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/ ... popcaploader_v6.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\Shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe (file missing)
O23 - Service: ositp4 - Unknown owner - C:\ositp4\ositp4.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Reply

Use magic Report

Post time 12-6-2007 07:48 PM | Show all posts
Hmmm rasa nya yg ni mungkin penyebab dia...

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)

cuba buang yg 2 ni...
pastu tgk ok ke tak
Reply

Use magic Report

 Author| Post time 12-6-2007 08:15 PM | Show all posts

Reply #12 syafthegeek's post

tak ok gak ler bro.. sama jer hasilnye..
Reply

Use magic Report

Follow Us
Post time 12-6-2007 08:24 PM | Show all posts
hmm yer ker...
apa kata cuba pkai software StartPCL
dia takyah install tapi bole check apa yg ada kat startup tu
Reply

Use magic Report

 Author| Post time 12-6-2007 08:33 PM | Show all posts

Reply #14 syafthegeek's post

ni aku ambik screenshot dr ccleaner ape yg ade kat startup aku... aku nmpk mcm x de yg weird...


http://luvly-eone.angelfire.com/registry/index.album/startup?i=3&s=1
Reply

Use magic Report


ADVERTISEMENT


Post time 12-6-2007 10:32 PM | Show all posts
Hi,

One of our other moderators asked me to take a look at this thread. You seem to be having a lot of problems with this system and what I'd like to do is rule out some possible non-malware related issues. While you do that, I will leave the HJT log in behind for any Responders to assist with any malware issues if remains.

The updated Adaware actually finds and removes this popup. But you also had the bad regedit.exe, notepad.exe, wordpad.exe, etc. So each reboot, the regedit would reinstall the bad stuff. You find that, but then each time notepad would run, the bad stuff would install again. That means every time you tried to save a Hijack This log (*.log files are opened with notepad), the bad files would be installed again. Getting rid of those .exe files was the key.

So search your hardrive for files that were accessed and created on the day your problem started, in your case maybe the files were created on dd/mm/yyyy at hh:mm AM/PM.

Try to search of your hard drive for files that were created and that match the dates and times you first started having problems, if you can remeber the date of course. Anyway you may find the following duplicate files that seem to be responsible for the trojans reinstalling on your system - WINDOWS directory all created on dd/mm/yyyy at hh:mm AM/PM, the files were NOTEPAD.EXE, PING.EXE, REGEDIT.EXE, WORDPAD.EXE. (remember these are duplicate files you may find and they will match the date the trojan installed on your system, don't delete your legit files of the same name)

Delete those duplicate files and the problem with the trojans reinstalling on reboot seemed to stop, except your real NOTEPAD.exe would still install all the trojan files again. So check the date it was created and it seemed to be legit other than it said it was modified dd/mm/yyyy at hh:mm AM/PM. Copy a NOTEPAD.EXE from your WINDOWS folder and pasting it in WINDOWS/SYSTEM32 folder and let it replace the altered NOTEPAD. Also be sure to turn on show hidden files just incase they are hidden on your system.

Reply

Use magic Report

Post time 12-6-2007 11:20 PM | Show all posts

Reply #19 luvly_eone's post

Reply

Use magic Report

Post time 13-6-2007 12:01 AM | Show all posts
Suspicious files from HJT:

F2 - REG:system.ini: Shell=explorer.exe, "C:\Documents and Settings\MOHD EZUAN'IZAM\Templates\18281\13418281.exe"
O3 - Toolbar: Alexa - {3CEFF6CD-6F08-4e4d-BCCD-FF7415288C3B} - C:\WINDOWS\system32\SHDOCVW.DLL
O8 - Extra context menu item: Alexa Web Search - http://client.alexa.com/holiday/script/actions/search.htm
O8 - Extra context menu item: Get Alexa Data - http://client.alexa.com/holiday/script/actions/sitedata.htm
O8 - Extra context menu item: Mail to a Friend... - http://client.alexa.com/holiday/script/actions/mailto.htm
O8 - Extra context menu item: See Related Links - http://client.alexa.com/holiday/script/actions/related.htm
O8 - Extra context menu item: Write a Review... - http://client.alexa.com/holiday/script/actions/review.htm
Reply

Use magic Report

Post time 13-6-2007 02:40 AM | Show all posts
Reply

Use magic Report

 Author| Post time 13-6-2007 06:47 PM | Show all posts
Bro...

Aku dah download,install and buat semua cadangan korang... tapi masih tak berjaya,

Also for Infophilia... I have done your suggestion but can't found any duplicate *.exe file for the whole month.

Anyway... computer aku ni takda  problem sangat.. semua program running very well and performance pun ok..

cuma menyemakkan mata jer regestry masa startup tu...

nak format masalah ler pulak sebab installer program untuk kerje aku ni tak boleh nak dapat.

[ Last edited by  trunks at 14-7-2007 09:03 PM ]
Reply

Use magic Report

Post time 14-6-2007 05:51 AM | Show all posts
F2 - REG:system.ini: Shell=explorer.exe, "C:\Documents and Settings\MOHD EZUAN'IZAM\Templates\18281\13418281.exe"


Cuba bukak regedit dlm safemode pastu check:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

Cari key 'Shell'. Pastikan cuma ada 'explorer.exe' je. Kalau ada yg lain dari tu, buang!
Pastu cari key 'UserInit'. Pastikan cuma ada 'C:\WINDOWS\system32\userinit.exe,'

cari fail C:\Documents and Settings\MOHD EZUAN'IZAM\Templates\18281\13418281.exe dan delete
Reply

Use magic Report

Post time 14-6-2007 05:37 PM | Show all posts

13418281.exe

cuba guna search function dan delete 13418281.exe ...ni bukan legal file...nama pun dah ganjil...->13418281.exe,sama ada spyware ataupun virus..
Reply

Use magic Report

Post time 14-6-2007 05:57 PM | Show all posts
Reply

Use magic Report


ADVERTISEMENT


 Author| Post time 15-6-2007 02:54 AM | Show all posts
dah buat semua... tapi masih belum berhasil daa..
Reply

Use magic Report

 Author| Post time 17-6-2007 03:59 PM | Show all posts

Reply #44 Xscape_War's post

ni aku paste screenshot

HKLM :

HKCU:

autorun:
Reply

Use magic Report

Post time 18-6-2007 11:13 PM | Show all posts
ko delete kat HKLM

- mywebsearch bar
- my websearch plugins
- PHIME2002A
- PHIMEASYNC

kat autorun run ko untick

HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\SHELL

C:\DOCUMENTSANDSETING..BLA BLA --- YG NI UNTICK

- restart
Reply

Use magic Report

 Author| Post time 19-6-2007 08:32 AM | Show all posts

Reply #46 Xscape_War's post

Dah try buat bro... mmg x settle gak masalah ni...
Reply

Use magic Report

12Next
Return to list New
You have to log in before you can reply Login | Register

Points Rules

 

ADVERTISEMENT


Forum Hot Topic

 

ADVERTISEMENT


 


ADVERTISEMENT
Follow Us

ADVERTISEMENT


Mobile|Archiver|Mobile*default|About Us|CariDotMy

12-12-2024 02:08 AM GMT+8 , Processed in 0.064728 second(s), 34 queries , Gzip On, Redis On.

Powered by Discuz! X3.4

Copyright © 2001-2021, Tencent Cloud.

Quick Reply To Top Return to the list